Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
ID: 05ad981a-a7c1-5f1f-b704-4ce869983365
STIX ID: report--05ad981a-a7c1-5f1f-b704-4ce869983365
Feed Name: GBHackers
Threat Score
Red Hat disclosed CVE-2026-18963, a critical (CVSS 3.1 9.1) vulnerability in the Red Hat Build of Keycloak's reset-credentials flow that lets unauthenticated remote attackers bypass password-reset email verification and set new passwords to seize user accounts; Red Hat issued fixes on August 18, 2026 for affected builds and advises applying updates immediately or disabling the "Forgot password" feature as a temporary mitigation while reviewing logs and invalidating suspicious sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
